Claude Skill

solana-dev

Routing hub for Solana development. Maps a task to the one reference to read first in the ext/ skill submodules or the kit's local skills.

LLM Mart · 0 points · 0 views 0 listing impressions 0 install-command copies
Virus-scanned Reviewed automatically before listing.

Full trust report

Download solanabr-ai-kit-.claude_skills-257443b.zip · 26 KB
Part of solanabr/ai-kit — 2 skills

Install

skills CLI npx skills add https://github.com/solanabr/ai-kit/tree/main/.claude/skills
Claude Code claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install solanabr-ai-kit@llmmart
Git git clone https://github.com/solanabr/ai-kit.git

The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole solanabr/ai-kit collection as a plugin from our marketplace. Git is the plain clone.

Skill manifest

Solana skill hub

Find the task, read the linked file, and follow further links only as needed. Paths are relative to this file.

When sources overlap: the program-code house rules in the project instruction file (CLAUDE.md, or AGENTS.md in --agents installs) win; a protocol's official skill wins for its own SDK (Jupiter, Metaplex, Helius); ext/solana-dev wins for general Solana work; sendai and community skills fill gaps only.

Programs

Task Read
Any program, client or test work (entry point) solana-dev SKILL.md
Anchor programs/anchor.md; upgrading to 1.x: migrating-v0.32-to-v1.md
Pinocchio, CU optimization programs/pinocchio.md
Account and PDA design programs/design-patterns.md
Tests: LiteSVM, Mollusk, Surfpool testing.md, surfpool/overview.md
Error codes, failing transactions common-errors.md
Toolchain version pairing compatibility-matrix.md
Security review security.md, safe-solana-builder (security-first scaffolding, Anchor/native/Pinocchio)
Financial math, Quasar zero-copy RUST.md, ANCHOR.md, QUASAR.md from quicknode-anchor; reference files only, skip that repo's SKILL.md workflow layer
Formal verification (Lean 4) qedgen from QEDGen; needs the qedgen CLI and MISTRAL_API_KEY
Port from Solidity/EVM eth-to-sol from eth-to-sol: type-mapping, pattern-mapping, stdlib-mapping, mental-model, translation/, security/, optimization/; concept map: solana-vs-evm.md

Anchor 1.x defaults this kit uses (not all spelled out upstream): SPL transfers through token_interface::transfer_checked, account space T::DISCRIMINATOR.len() + T::INIT_SPACE, Rust LiteSVM tests under programs/<name>/tests/ (anchor test runs Surfpool).

Clients and frontend

Task Read
Wallet connection, React hooks, @solana/kit UI frontend.md
Transactions, Kit and web3.js boundary kit-web3-interop.md
web3.js to Kit migration solana-kit-migration/, solana-kit/
Clients generated from an IDL (Codama, Shank) idl-codegen.md
Payments, Solana Pay, Kora payments.md
Official doc links resources.md
Vercel, Next.js, AI SDK, v0 ext/vercel/skills/ from Vercel

Tokens and NFTs

Task Read
Token-2022 extensions (hooks, fees, metadata, soulbound) token-2022.md
Confidential transfers confidential-transfers.md
NFTs: Core, Token Metadata, Bubblegum, Candy Machine, Umi metaplex (official)

DeFi, RPC and data

Task Read
Jupiter swap, lend, perps, trigger, recurring integrating-jupiter (official); also jupiter-lend, jupiter-swap-migration, jupiter-vrfd
Helius RPC, DAS, webhooks, Sender, priority fees helius (official)
SVM internals, consensus, validators, SIMDs svm

Other protocols from SendAI: perps phoenix and leverage lavarage; AMMs raydium, meteora, orca; lending kamino, marginfi; LSTs sanctum; launches pumpfun; oracles pyth, switchboard; multisig squads; bridging debridge, lifi; encrypted compute arcium; ZK compression light-protocol; data birdeye, wallet-analysis; RPC carbium, quicknode; order book manifest; order flow dflow; on-chain games magicblock; account cleanup sol-incinerator; agents solana-agent-kit; wallets phantom-connect; scanning vulnhunter. SendAI's own jupiter, metaplex and helius folders are older copies; the official skills above supersede them.

Security tooling

Deploy, infra, backend

Games and mobile

Ideas, pitch, go-to-market

Add-ons

skill-registry.json lists opt-in tools the kit doesn't bundle; install one only when the user asks. Wider ecosystem catalogs: ext/solana-new/cli/data/.

Files (ai-kit)
  • hackathon
    • SKILL.md 3.7 KB
      ---
      name: hackathon
      description: Prepare a winning hackathon submission. Use when the user says "hackathon submission", "submit to hackathon", "demo script", "demo video", "which track should I enter", "Colosseum", "help me win the hackathon", or asks about hackathon grants and Superteam Earn.
      user-invocable: true
      ---
      
      <!-- Adapted from sendaifun/solana-new (submit-to-hackathon, apply-grant), MIT © 2026 SendAI and Superteam. Telemetry removed. -->
      
      # Hackathon Submission
      
      Track choice → scannable description → <3-min demo script → checklist. Optimize for a judge who has 90 seconds, not a reader who has 10 minutes.
      
      ## Context handoff
      
      At start, read `.claude/context/idea.md` and `.claude/context/build.md` if present — pull the pitch, wedge, and what actually works from them instead of asking again.
      
      ## Workflow
      
      ### 1. Pick the least-crowded track
      
      Winning a thin track beats placing in a fat one. Per candidate track: estimate entry volume, fit with what's actually built, and judge appetite (sponsor tracks often have the fewest serious entries).
      
      - Winner patterns + track history: [hackathon-winners.md](../ext/solana-new/skills/data/colosseum/hackathon-winners.md) — every Colosseum grand champion and track winner, with what they built
      - Live crowdedness check: [ext/colosseum](../ext/colosseum/skills/colosseum-copilot/SKILL.md) — query 5,400+ past submissions for cluster density and gaps (requires `COLOSSEUM_COPILOT_PAT`)
      
      ### 2. Write a scannable description
      
      **Judges read 100+ submissions.** Yours gets one skim deciding whether it gets a real read:
      
      - Tagline: what it does, one sentence, no jargon
      - First paragraph: problem + who has it
      - Bold the one thing that's novel
      - "What works today" list — demo-able claims only, never roadmap dressed as product
      - Why Solana (one concrete reason: speed, fees, composability with X)
      
      Full structure (200–500 words, paragraph-by-paragraph): [hackathon-submission-guide.md](../ext/solana-new/skills/launch/submit-to-hackathon/references/hackathon-submission-guide.md). Score the draft against [judging-criteria.md](../ext/solana-new/skills/launch/submit-to-hackathon/references/judging-criteria.md) before submitting.
      
      ### 3. Demo script (<3 minutes)
      
      | Time | Beat |
      |------|------|
      | 0:00–0:20 | Problem — one user, one pain, no market-size slides |
      | 0:20–0:40 | What you built, one sentence + UI first appears |
      | 0:40–2:10 | The demo — one happy path, real data, on-chain proof (explorer tx) |
      | 2:10–2:40 | The novel part — the thing competitors don't have |
      | 2:40–3:00 | Traction/team one-liner + the ask |
      
      Shot-by-shot template and recording tips: [demo-video-script.md](../ext/solana-new/skills/launch/submit-to-hackathon/references/demo-video-script.md). Rule: if the demo can fail live, record it.
      
      ### 4. Submission checklist
      
      - [ ] Track chosen by crowdedness, not vanity
      - [ ] Tagline passes the "non-crypto friend" test
      - [ ] Description scannable in 90 seconds (bold claims, short paragraphs)
      - [ ] Demo video <3 min, real transaction shown
      - [ ] Repo public, README quickstart actually works from clone
      - [ ] Deployed link (devnet OK) + program ID listed
      - [ ] Team and contact info complete
      - [ ] Pitch deck attached if track requires one — use [pitch-deck](../pitch-deck/SKILL.md)
      
      ## After the hackathon: grants
      
      Losing the track doesn't mean losing the funding. Same artifacts (description, demo, deck) feed grant applications:
      
      - **Superteam Earn** (earn.superteam.fun) — bounties + grants up to ~$10k USDC equivalent, fast cycles, regional Superteams
      - **Solana Foundation grants** — milestone-based, public-good angle; reuse the scannable description with an ecosystem-benefit paragraph
      - Grant-shaped ideas dataset: [superteam-ideas.json](../ext/solana-new/skills/data/ideas/superteam-ideas.json)
      
  • idea-sprint
    • SKILL.md 5.2 KB
      ---
      name: idea-sprint
      description: Find and validate what to build in crypto. Use when the user asks "what should I build", "validate this idea", "is this worth building", "find me a startup idea", "crypto idea", or wants blunt feedback on a project concept before writing code.
      user-invocable: true
      ---
      
      <!-- Adapted from sendaifun/solana-new (find-next-crypto-idea, validate-idea), MIT © 2026 SendAI and Superteam. Telemetry removed. -->
      
      # Idea Sprint
      
      Interview → necessity gate → 3 candidates → score → go/no-go. Output is a decision, not a brainstorm.
      
      ## Context handoff
      
      - At start: read `.claude/context/idea.md` and `.claude/context/build.md` if present — resume from prior state instead of re-interviewing.
      - On completion: write/update `.claude/context/idea.md` with the chosen idea, scores, validation evidence, and open risks. Downstream skills (pitch-deck, hackathon) read it.
      
      ## Workflow
      
      ### 1. Blunt interview
      
      No flattery. Short, pointed questions, one at a time, until three things are explicit:
      
      - **Edge** — what the founder knows/can do that most can't (domain, distribution, tech)
      - **Constraint** — time, money, team, chain commitments
      - **Wedge** — the niche entry point, not the end-state vision
      
      Push back on vague answers. "DeFi for everyone" is not a wedge. Full question bank: [interview-framework.md](../ext/solana-new/skills/idea/find-next-crypto-idea/references/interview-framework.md).
      
      ### 2. Crypto-necessity gate
      
      Kill question: **"What gets worse if I remove the blockchain?"** If the answer is vague, aesthetic, or marketing-driven — redirect the idea before scoring it. Pass criteria and redirect patterns: [crypto-necessity-test.md](../ext/solana-new/skills/idea/find-next-crypto-idea/references/crypto-necessity-test.md).
      
      ### 3. Exactly 3 candidates
      
      Generate three **diverse** candidates (different mechanisms/markets, not three flavors of one idea). For each:
      
      - One-line pitch + target user
      - **Winner case** — what's true in 18 months if it works
      - **Bear case** — the most likely way it dies
      
      Seed from datasets + live landscape (below), then combine with fresh research. Datasets are inspiration, not constraints.
      
      ### 4. Score /15
      
      Each candidate, 0–3 per dimension (full anchors: [scoring-rubric.md](../ext/solana-new/skills/idea/find-next-crypto-idea/references/scoring-rubric.md)):
      
      | Dimension | 3 means |
      |-----------|---------|
      | Founder fit | unfair advantage |
      | MVP speed | shippable in under a week |
      | Distribution | first ten users are obvious |
      | Market pull | people already paying for bad alternatives |
      | Revenue path | clear monetization story |
      
      ### 5. Validate + go/no-go
      
      Check demand signals against [customer-signal-rubric.md](../ext/solana-new/skills/idea/validate-idea/references/customer-signal-rubric.md) — manual workarounds, active forks, bounties, on-chain activity = real; likes and "cool idea" replies = noise. Sprint structure: [validation-framework.md](../ext/solana-new/skills/idea/validate-idea/references/validation-framework.md).
      
      - **≥ 8/15** → go. Write `idea.md`, suggest `/scaffold` next.
      - **6–7** → conditional: name the one dimension to de-risk first.
      - **< 6** → strong no-go. **Every no-go gets a pivot suggestion** — use [pivot-or-persist.md](../ext/solana-new/skills/idea/validate-idea/references/pivot-or-persist.md).
      
      ### 6. Write `.claude/context/idea.md`
      
      Chosen idea, wedge, scores table, demand evidence, bear case, next step.
      
      ## Idea datasets (inert JSON, ~515 entries)
      
      In [../ext/solana-new/skills/data/ideas/](../ext/solana-new/skills/data/ideas/):
      
      - [web3-ideas-combined.json](../ext/solana-new/skills/data/ideas/web3-ideas-combined.json) — master list ([summary](../ext/solana-new/skills/data/ideas/web3-ideas-summary.json))
      - [a16z-big-ideas-2025.json](../ext/solana-new/skills/data/ideas/a16z-big-ideas-2025.json), [a16z-state-of-crypto-2025.json](../ext/solana-new/skills/data/ideas/a16z-state-of-crypto-2025.json)
      - [yc-requests-for-startups.json](../ext/solana-new/skills/data/ideas/yc-requests-for-startups.json), [yc-crypto-companies.json](../ext/solana-new/skills/data/ideas/yc-crypto-companies.json)
      - [alliance-ideas.json](../ext/solana-new/skills/data/ideas/alliance-ideas.json), [superteam-ideas.json](../ext/solana-new/skills/data/ideas/superteam-ideas.json)
      - [rwa-defi-2026-ideas.json](../ext/solana-new/skills/data/ideas/rwa-defi-2026-ideas.json), [yash-defi-2024-ideas.json](../ext/solana-new/skills/data/ideas/yash-defi-2024-ideas.json)
      
      Idea-source guides (markdown commentary on the same sources): [../ext/solana-new/skills/data/guides/](../ext/solana-new/skills/data/guides/) — plus [source-map.md](../ext/solana-new/skills/idea/find-next-crypto-idea/references/source-map.md) and [research-playbook.md](../ext/solana-new/skills/idea/find-next-crypto-idea/references/research-playbook.md) for where/how to research live.
      
      ## Live hackathon landscape
      
      [ext/colosseum](../ext/colosseum/skills/colosseum-copilot/SKILL.md) — 5,400+ Colosseum submissions for crowdedness checks, winner patterns, and gap analysis (requires `COLOSSEUM_COPILOT_PAT`).
      
      ## Output format
      
      Report spec (3 ranked candidates, scores, decision): [output-spec.md](../ext/solana-new/skills/idea/find-next-crypto-idea/references/output-spec.md).
      
  • pitch-deck
    • SKILL.md 4.1 KB
      ---
      name: pitch-deck
      description: Build a pitch deck for a crypto project. Use when the user says "pitch deck", "demo day", "investor presentation", "grant application slides", "accelerator application", "help me pitch", or needs slides for a hackathon final.
      user-invocable: true
      ---
      
      <!-- Adapted from sendaifun/solana-new (create-pitch-deck), MIT © 2026 SendAI and Superteam. Telemetry removed. -->
      
      # Pitch Deck
      
      Interview → detect audience → pick narrative → build slides with speaking notes → self-score → objection prep.
      
      ## Context handoff
      
      At start, read `.claude/context/idea.md` and `.claude/context/build.md` if present — pre-fill problem, wedge, traction, and stack from them; only ask what's missing.
      
      ## Workflow
      
      ### 1. 12-question interview
      
      Blunt, one at a time, skipping anything already answered by context files:
      
      1. What does it do, in one sentence a non-crypto person understands?
      2. Who exactly has the problem, and how painful is it (evidence)?
      3. Why does this need a blockchain?
      4. Why Solana specifically?
      5. What works *today* (demo-able) vs. roadmap?
      6. Traction numbers — users, volume, TVL, signups, waitlist?
      7. Who is the team and what's the unfair edge?
      8. Competitors and your moat?
      9. Business model — who pays, when?
      10. Who is the audience for this deck (judges, VCs, grant committee, accelerator)?
      11. The ask — prize, check size, grant amount, admission?
      12. Biggest weakness you're afraid they'll ask about?
      
      ### 2. Audience detection → slide set
      
      Q10 decides the slide set — full breakdown in [investor-audience-guide.md](../ext/solana-new/skills/launch/create-pitch-deck/references/investor-audience-guide.md):
      
      | Audience | Emphasis | Length |
      |----------|----------|--------|
      | Hackathon judges | working demo, technical novelty, why-Solana | 5–7 slides |
      | VC | market size, traction slope, team, moat, ask | 10–12 |
      | Grant committee | ecosystem benefit, public-good angle, milestones, budget | 8–10 |
      | Accelerator | team velocity, learning rate, wedge → expansion path | 8–10 |
      
      Slide-by-slide order per audience: [pitch-structure.md](../ext/solana-new/skills/launch/create-pitch-deck/references/pitch-structure.md).
      
      ### 3. Narrative framework
      
      Pick one backbone and state why — PAS (obvious pain, hackathons), 6-Part Investor Arc (VC), BAB (before/after/bridge), Hero's Journey (founder-story-driven), Pixar (narrative momentum). Definitions, slide mappings, and crypto examples: [storytelling-frameworks.md](../ext/solana-new/skills/launch/create-pitch-deck/references/storytelling-frameworks.md).
      
      ### 4. Build slides + speaking notes
      
      For each slide: headline (a claim, not a label), 3–5 supporting points, visual suggestion, and 30–60s speaking notes. Use:
      
      - [slide-templates.md](../ext/solana-new/skills/launch/create-pitch-deck/references/slide-templates.md) — per-slide-type templates
      - [deck-design-system.md](../ext/solana-new/skills/launch/create-pitch-deck/references/deck-design-system.md) — typography, layout, color rules
      - [crypto-pitch-examples.md](../ext/solana-new/skills/launch/create-pitch-deck/references/crypto-pitch-examples.md) — real decks that worked
      - [pitch-reference-sources.md](../ext/solana-new/skills/launch/create-pitch-deck/references/pitch-reference-sources.md) — primary sources
      
      ### 5. Self-score vs audience rubric
      
      Score the draft against the audience's actual criteria (clarity, credibility, demo strength, ask specificity) and against [crypto-pitch-mistakes.md](../ext/solana-new/skills/launch/create-pitch-deck/references/crypto-pitch-mistakes.md) — flag every mistake the deck still commits, fix, re-score. Don't present a deck you'd score below 8/10.
      
      ### 6. Objection-prep Q&A
      
      From Q12 + the weakest scored dimension, draft the 8–10 hardest questions this audience will ask, each with a tight 30-second answer. Hostile-question drilling beats slide polish.
      
      ## Output
      
      - Deck outline (markdown, one section per slide: headline / points / visual / speaking notes)
      - Framework choice + one-line rationale
      - Self-score with the fixes applied
      - Objection Q&A sheet
      
      Need an actual rendered deck file (.pptx)? Hand the outline to the pptx skill if available.
      
  • backend-async.md 4.7 KB
    ---
    name: backend-async
    description: "Solana-specific rules for Rust backends and indexers: async RPC client, commitment, RPC limits, stream reconnect and backfill, idempotent indexing, send/confirm with priority fees."
    ---
    
    # Rust backends and indexers
    
    Only the Solana-specific parts; Axum, Tokio and SQLx are used as usual. Helius APIs (Laserstream, Sender, webhooks): [helius skill](ext/helius/helius-skills/helius/SKILL.md).
    
    ## RPC client
    
    - Use the nonblocking `RpcClient` (`solana_rpc_client::nonblocking::rpc_client`) in an `Arc`, with a timeout (`new_with_timeout_and_commitment`). The blocking client runs its own runtime via `block_in_place`, which panics on a current-thread runtime (the `#[tokio::test]` default) and parks a worker otherwise; `anchor-client` needs `features = ["async"]`.
    - Keep `spawn_blocking` for CPU work (bulk signing, proofs), not RPC.
    - Batch reads: `get_multiple_accounts` (100 keys), `data_slice`, memcmp filters. Unfiltered `getProgramAccounts` is slow or disabled on most providers; index instead. `getSignaturesForAddress` pages at 1,000 via `before`/`until`.
    - Retry 429, 5xx and timeouts with jittered backoff and `Retry-After`, not simulation or parameter errors. Public endpoints are for development.
    - Transaction v1 is live on mainnet: pass `max_supported_transaction_version: Some(1)` to `get_transaction`/`get_block`, or a single v1 transaction fails the whole block. Geyser detection and 4.x crates: [transactions-v1.md](ext/solana-dev/skills/solana-dev/references/transactions-v1.md).
    
    ## Commitment
    
    - `confirmed` for API reads and blockhashes; `processed` only if you handle forks yourself.
    - `finalized` before irreversible off-chain effects (crediting deposits, payouts), or treat `confirmed` as provisional and reconcile at finalized.
    - Fetch the blockhash and run preflight at the same commitment; a blockhash newer than the preflight bank fails with `BlockhashNotFound`.
    - Read your own writes with `min_context_slot` set to the write's slot; load-balanced RPCs otherwise answer from a lagging node.
    
    ## Streams
    
    - Subscriptions drop silently and never replay. Run a watchdog (a slot subscription as heartbeat) and resubscribe with backoff.
    - On reconnect, backfill the gap: page `getSignaturesForAddress(program, until = last_processed_signature)` backward, then process oldest first through the same idempotent path. Laserstream/Yellowstone take `from_slot = last_processed_slot` ([Laserstream](ext/helius/helius-skills/helius/references/laserstream.md) replays about 24 h).
    - Yellowstone gRPC: answer server pings with a ping `SubscribeRequest` or load balancers drop the stream; pin `yellowstone-grpc-proto >= 12.6.0` so v1 message config decodes.
    - Decode events from `emit_cpi!` inner-instruction data or from instructions, not logs: logs truncate, and `logsSubscribe` carries no account data.
    
    ## Indexer rules
    
    - Idempotent writes keyed by `signature` for transactions and `(signature, instruction path)` for events (one transaction can emit several); `ON CONFLICT DO NOTHING`.
    - Stamp rows with `slot` (plus Geyser `write_version` for accounts) and upsert account state only when `(slot, write_version)` is newer: backfill and live data interleave.
    - Ingest at `confirmed`, mark rows provisional, promote once the slot finalizes, delete rows from slots that never do. At `processed`, also handle Geyser dead-slot status.
    - Commit the checkpoint (last slot or signature) in the same DB transaction as its rows.
    - Failed transactions (`meta.err`) pay fees and appear in signature lists; skip their state changes.
    - Decode with the IDL version live at that slot; upgrades change layouts.
    - Alert on ingestion lag (tip slot minus last processed slot).
    
    ## Sending transactions
    
    - `get_latest_blockhash_with_commitment(confirmed)` also returns `last_valid_block_height`; expiry is by block height, not time.
    - Simulate once to size the compute limit (consumed plus 10-20%); the v0 fee is limit x price, so overshooting wastes lamports. Price from `getRecentPrioritizationFees` over the writable accounts you lock (capped percentile) or [a provider estimate](ext/helius/helius-skills/helius/references/priority-fees.md). In v1 transactions the priority fee is a lamport total, and unset compute and data limits are zero, not defaults.
    - Send with `skip_preflight: true` (already simulated) and `max_retries: Some(0)`; rebroadcast the same signed bytes every ~2 s while polling `get_signature_statuses`, until confirmed or the block height passes `last_valid_block_height`.
    - Re-sign with a fresh blockhash only after the old one expired, or both can land. Durable nonces for slow or multi-party signing.
    - Landing services (Helius Sender, Jito) add tip and preflight rules: [sender.md](ext/helius/helius-skills/helius/references/sender.md).
    
  • deployment.md 8 KB
    ---
    name: deployment
    description: "Program deployment runbook: devnet then mainnet, verifiable builds, Squads v4 multisig upgrades, upgrade-authority staging, rollback, and cost estimation."
    ---
    
    # Deployment
    
    The runbook behind `/deploy`; `/setup-ci-cd` owns the CI workflow. Kit policy: devnet first, and mainnet only with the user's explicit go-ahead. Get that go-ahead yourself; do not rely on a tool gate to stop you. Claude Code adds one — a PreToolUse hook matching only the literal `anchor deploy` and `solana program deploy`, blocking them when the command or the configured cluster says mainnet unless prefixed with `CONFIRM_MAINNET=1`. Even there, `anchor program deploy|upgrade`, `anchor upgrade`, `solana program write-buffer`, `set-upgrade-authority` and `--final` pass unchecked. Runtimes that do not read `settings.json` (Codex, opencode) have no gate at all, so every mainnet command needs explicit confirmation first.
    
    ## Anchor 1.x changes that affect deploys
    
    - `anchor deploy` also uploads the IDL to Program Metadata (`--no-idl` skips it). `anchor idl init|upgrade --filepath target/idl/<name>.json` republishes it; the program ID comes from the IDL's `address`.
    - A program deployed with Anchor 0.32 or older that has a legacy IDL account: close it with the 0.32 CLI (`anchor idl close <PROGRAM_ID>`) while the 0.32 binary is still deployed, then deploy the 1.x binary, or that rent is stranded. See [migrating-v0.32-to-v1.md](ext/solana-dev/skills/solana-dev/references/anchor/migrating-v0.32-to-v1.md), sections 5 and 10.
    - Anchor no longer shells out to the `solana` CLI. Loader flags go after `--`: `anchor deploy -- --with-compute-unit-price 50000`. `anchor program deploy|upgrade|write-buffer|set-buffer-authority|set-upgrade-authority|show|dump|close` mirror the `solana program` commands used below, and newer CLIs deprecate top-level `anchor deploy`/`anchor upgrade` in their favor.
    - `anchor verify <PROGRAM_ID>` wraps `solana-verify` since 0.32; binaries built with older Anchor will not verify with it.
    
    ## Build once, deploy that artifact
    
    1. `/test-rust` green, `/audit-solana` for code that holds funds, `/profile-cu` baseline recorded.
    2. `anchor build` for the IDL and types, then `solana-verify build --library-name <lib>` last. It rebuilds `target/deploy/<lib>.so` in Docker, and it is the build that `solana-verify verify-from-repo` and `anchor verify` reproduce. Any later `anchor build` or `cargo build-sbf` overwrites that file with a non-deterministic binary.
    3. Record `solana-verify get-executable-hash target/deploy/<lib>.so` next to the release commit.
    4. Back up `target/deploy/<name>-keypair.json` (it is the program address) outside the repo before the first deploy.
    
    ## Devnet
    
    ```bash
    anchor deploy -p <name> --provider.cluster devnet          # first deploy
    anchor upgrade target/deploy/<lib>.so --program-id <PROGRAM_ID> --provider.cluster devnet
    solana program show <PROGRAM_ID> -u devnet
    solana logs <PROGRAM_ID> -u devnet                         # while exercising each instruction
    ```
    
    Rehearse the exact mainnet flow here, including a multisig upgrade through a devnet Squad.
    
    ## Cost estimation
    
    - Program rent: `solana rent $(( $(wc -c < target/deploy/<lib>.so) + 45 ))` (ProgramData has a 45-byte header). With `--max-len <N>` to reserve growth room, use N + 45.
    - A buffer holding about the same rent exists while writing; the deploy or upgrade instruction drains it to the payer (first deploy) or the spill account (upgrade).
    - Writing takes many transactions (roughly one per KB of program). On mainnet add `--with-compute-unit-price <micro-lamports>`, use `--use-rpc` to send writes through the RPC instead of directly to leaders (more reliable from CI or behind NAT), and `--max-sign-attempts` for blockhash expiry. Use a paid RPC; public endpoints rate-limit the writes.
    - A failed deploy leaves a funded buffer: list with `solana program show --buffers` and reclaim with `solana program close --buffers`, or resume with the printed seed phrase via `solana-keygen recover -o buffer.json` and `solana program deploy --buffer buffer.json ...`.
    
    ## Mainnet first deploy
    
    ```bash
    CONFIRM_MAINNET=1 anchor deploy -p <name> --provider.cluster mainnet -- --with-compute-unit-price <N>
    solana program show <PROGRAM_ID> -u mainnet-beta
    anchor idl fetch <PROGRAM_ID> --provider.cluster mainnet    # diff against target/idl/<name>.json
    solana-verify verify-from-repo -um --program-id <PROGRAM_ID> <REPO_URL> --commit-hash <SHA> \
      --library-name <lib> --mount-path <program dir> --remote  # accept the verify-PDA upload
    ```
    
    ## Upgrade-authority staging
    
    1. Launch to about 3 months: authority on a hardware-wallet deployer key, so fixes ship fast while bugs surface.
    2. Once stable (about 3 months, or earlier when meaningful value is at stake): move it to the Squads v4 vault PDA (`getVaultPda({ multisigPda, index: 0 })`, the "vault" address in the Squads app). The multisig account itself cannot sign, so authority given to it is lost.
       `solana program set-upgrade-authority <PROGRAM_ID> --new-upgrade-authority <VAULT_PDA> --skip-new-upgrade-authority-signer-check -u mainnet-beta`
       The skip flag is needed because a PDA cannot co-sign; verify the address first, a wrong one is unrecoverable.
    3. After an audit and a long mainnet history: `solana program set-upgrade-authority <PROGRAM_ID> --final`. Irreversible, and it removes every rollback path.
    
    ## Mainnet upgrade through Squads v4
    
    ```bash
    solana program write-buffer target/deploy/<lib>.so -u mainnet-beta --with-compute-unit-price <N> --use-rpc
    solana program set-buffer-authority <BUFFER> --new-buffer-authority <VAULT_PDA> -u mainnet-beta
    solana-verify get-buffer-hash -um <BUFFER>                  # must equal the executable hash; reviewers check it
    solana program extend <PROGRAM_ID> <BYTES> -u mainnet-beta  # only if the .so outgrew the current Data Length
    ```
    
    `write-buffer` needs the buffer authority to sign each write, so write with the deployer key and hand the buffer to the vault afterwards. `extend` is permissionless, so the deployer key can pay for it. Then create the upgrade proposal in the Squads app's program manager (buffer plus a spill address for the refund), collect approvals, and execute. Afterwards:
    
    - `solana-verify get-program-hash -um <PROGRAM_ID>` equals the executable hash.
    - Refresh verification through the multisig: `solana-verify export-pda-tx <REPO_URL> --program-id <PROGRAM_ID> --uploader <VAULT_PDA> --encoding base58 --compute-unit-price 0`, import it into the Squads transaction builder, execute, then `solana-verify remote submit-job --program-id <PROGRAM_ID> --uploader <VAULT_PDA>`.
    
    Squads SDK details (vault PDA, proposals): [squads skill](ext/sendai/skills/squads/SKILL.md).
    
    ## Rollback
    
    - Before every upgrade: `solana program dump <PROGRAM_ID> backup-<version>.so -u mainnet-beta`, and keep each release's verified `.so` and hash.
    - Rolling back is another upgrade to the previous binary through the same buffer and multisig flow (devnet: `anchor upgrade <old>.so --program-id <PROGRAM_ID> --provider.cluster devnet`).
    - The previous binary must still read current account layouts. Ship layout changes additively (version field, `realloc`) so rollback stays possible; strategies in [program-upgrade-guide.md](ext/solana-new/skills/launch/deploy-to-mainnet/references/program-upgrade-guide.md).
    - An emergency pause exists only if every instruction already checks a pause flag; design it in before launch. A `--final` program cannot be rolled back.
    
    ## CI jobs
    
    The workflow file comes from `/setup-ci-cd`; it needs these jobs:
    
    - build: pinned Anchor (avm) and Agave versions, `anchor build` then `solana-verify build`, publish the `.so`, IDL and executable hash as artifacts.
    - test: `cargo test` / `anchor test` (LiteSVM, Surfpool), `cargo clippy -- -D warnings`, `cargo audit`.
    - deploy-devnet: on the integration branch, with a devnet-only key from CI secrets.
    - mainnet-buffer: write the buffer and move its authority to the Squads vault. CI never holds the mainnet upgrade authority.
    - verify: `solana-verify verify-from-repo --remote` against the release commit after the multisig executes.
    
  • skill-registry.json 30.5 KB
    {
      "version": "1.0",
      "updated": "2026-06-15",
      "entries": [
        {
          "id": "anthropic-skills",
          "name": "Anthropic Skills",
          "type": "skill",
          "domain": "productivity",
          "description": "Anthropic's official skill collection; net-new sub-skills not in the bundled office set: theme-factory, mcp-builder, webapp-testing, canvas-design, algorithmic-art, web-artifacts-builder.",
          "source": "https://github.com/anthropics/skills",
          "install": { "method": "plugin-marketplace", "command": "/plugin marketplace add anthropics/skills", "env": [] },
          "license": "mixed: example-skills Apache-2.0; docx/pdf/pptx/xlsx source-available (not OSS)",
          "maintainer": "anthropics",
          "signal": { "stars": 151000, "last_commit": "2026-06-09", "reputability": "official" },
          "default_installed": false,
          "safety": "clean (curl references are Claude-API doc examples, not installers); doc set is source-available — note the license split",
          "tags": ["theme-factory", "mcp-builder", "webapp-testing", "canvas-design", "algorithmic-art", "web-artifacts-builder", "official"]
        },
        {
          "id": "anthropic-claude-code-plugins",
          "name": "Anthropic Claude Code Plugins",
          "type": "plugin",
          "domain": "dev-workflow",
          "description": "Anthropic-authored Claude Code plugins: code-review, pr-review-toolkit, feature-dev, security-guidance. Complementary to the kit's /diff-review + cso/audit-infra (note the overlap).",
          "source": "https://github.com/anthropics/claude-code",
          "install": { "method": "plugin-marketplace", "command": "/plugin marketplace add anthropics/claude-code", "env": [] },
          "license": "Anthropic-commercial-ToS (not OSI)",
          "maintainer": "anthropics",
          "signal": { "stars": 132567, "last_commit": "2026-06-15", "reputability": "official" },
          "default_installed": false,
          "safety": "clean (Anthropic-authored; security-guidance is itself a safety hook); overlaps the kit's /diff-review + cso/audit-infra",
          "tags": ["code-review", "pr-review", "feature-dev", "security-guidance", "official"]
        },
        {
          "id": "wshobson-agents",
          "name": "wshobson Agents Marketplace",
          "type": "plugin",
          "domain": "dev-workflow",
          "description": "Multi-harness agent/command/skill plugin marketplace for general dev workflows.",
          "source": "https://github.com/wshobson/agents",
          "install": { "method": "plugin-marketplace", "command": "/plugin marketplace add wshobson/agents", "env": [] },
          "license": "MIT",
          "maintainer": "wshobson",
          "signal": { "stars": 36800, "last_commit": "2026-06-15", "reputability": "individual" },
          "default_installed": false,
          "safety": "clean",
          "tags": ["agents", "commands", "workflow", "marketplace"]
        },
        {
          "id": "get-shit-done",
          "name": "Get Shit Done (GSD)",
          "type": "template-repo",
          "domain": "dev-workflow",
          "description": "Spec-driven / meta-prompting workflow system (agents + commands).",
          "source": "https://github.com/gsd-build/get-shit-done",
          "install": { "method": "git-clone", "command": "git clone https://github.com/gsd-build/get-shit-done", "env": [] },
          "license": "MIT",
          "maintainer": "gsd-build",
          "signal": { "stars": 64000, "last_commit": "2026-05-31", "reputability": "org" },
          "default_installed": false,
          "safety": "clean (star count is web-search-inflated; treat as a floor)",
          "tags": ["spec-driven", "meta-prompting", "workflow", "agents", "commands"]
        },
        {
          "id": "get-shit-pretty",
          "name": "Get Shit Pretty (GSP)",
          "type": "template-repo",
          "domain": "frontend-design",
          "description": "Design-engineering system for AI coding agents (the design counterpart to GSD): 45+ skills + 13 sub-agents covering brand strategy, identity, design systems, UI build, accessibility, and critique via a dual-diamond pipeline, with 35 style presets. Not Solana-specific.",
          "source": "https://github.com/jubscodes/get-shit-pretty",
          "install": { "method": "npx", "command": "pnpm dlx get-shit-pretty   # or: bunx get-shit-pretty", "env": ["FIGMA_ACCESS_TOKEN (optional, for the bundled Figma MCP)"] },
          "license": "MIT",
          "maintainer": "jubscodes",
          "signal": { "stars": 43, "last_commit": "2026-06-07", "reputability": "individual" },
          "default_installed": false,
          "safety": "caution: ships auto-running Claude Code hooks (gsp/hooks/hooks.json) + bin/install.js merges hooks+statusline into settings.json — review before installing; otherwise MIT, no telemetry/curl|sh",
          "tags": ["design", "branding", "design-systems", "ui-polish", "frontend", "accessibility", "claude-code", "hooks"]
        },
        {
          "id": "dev-browser",
          "name": "Dev Browser",
          "type": "skill",
          "domain": "testing-qa",
          "description": "Gives the agent a real web browser for frontend QA, testing, and scraping.",
          "source": "https://github.com/SawyerHood/dev-browser",
          "install": { "method": "submodule", "command": "git submodule add https://github.com/SawyerHood/dev-browser .claude/skills/ext/dev-browser", "env": [] },
          "license": "MIT",
          "maintainer": "SawyerHood",
          "signal": { "stars": 6300, "last_commit": "2026-06-05", "reputability": "individual" },
          "default_installed": false,
          "safety": "clean",
          "tags": ["browser", "testing", "qa", "frontend"]
        },
        {
          "id": "ios-simulator-skill",
          "name": "iOS Simulator Skill",
          "type": "skill",
          "domain": "testing-qa",
          "description": "xcodebuild wrapper to drive the iOS Simulator; pairs with the kit's build-mobile.",
          "source": "https://github.com/conorluddy/ios-simulator-skill",
          "install": { "method": "submodule", "command": "git submodule add https://github.com/conorluddy/ios-simulator-skill .claude/skills/ext/ios-simulator", "env": [] },
          "license": "MIT",
          "maintainer": "conorluddy",
          "signal": { "stars": 1100, "last_commit": "2026-06-14", "reputability": "individual" },
          "default_installed": false,
          "safety": "clean",
          "tags": ["ios", "simulator", "xcode", "mobile", "testing"]
        },
        {
          "id": "frontend-slides",
          "name": "Frontend Slides",
          "type": "skill",
          "domain": "frontend-design",
          "description": "Build animation-rich HTML slide decks (synergy with the kit's pitch-deck).",
          "source": "https://github.com/zarazhangrui/frontend-slides",
          "install": { "method": "submodule", "command": "git submodule add https://github.com/zarazhangrui/frontend-slides .claude/skills/ext/frontend-slides", "env": [] },
          "license": "MIT",
          "maintainer": "zarazhangrui",
          "signal": { "stars": 21785, "last_commit": "2026-06-13", "reputability": "individual" },
          "default_installed": false,
          "safety": "clean",
          "tags": ["slides", "presentation", "html", "animation", "frontend"]
        },
        {
          "id": "anydesign",
          "name": "AnyDesign",
          "type": "skill",
          "domain": "frontend-design",
          "description": "Turn an image / URL / Figma reference into design.md design tokens; closest genre-mate to animation-principles.",
          "source": "https://github.com/uxKero/anydesign",
          "install": { "method": "submodule", "command": "git submodule add https://github.com/uxKero/anydesign .claude/skills/ext/anydesign", "env": [] },
          "license": "MIT",
          "maintainer": "uxKero",
          "signal": { "stars": 109, "last_commit": "2026-06-11", "reputability": "individual" },
          "default_installed": false,
          "safety": "clean",
          "tags": ["design-tokens", "figma", "ui", "frontend"]
        },
        {
          "id": "webgpu-claude-skill",
          "name": "WebGPU Claude Skill",
          "type": "skill",
          "domain": "frontend-design",
          "description": "WebGPU + Three.js graphics skill for the browser.",
          "source": "https://github.com/dgreenheck/webgpu-claude-skill",
          "install": { "method": "submodule", "command": "git submodule add https://github.com/dgreenheck/webgpu-claude-skill .claude/skills/ext/webgpu", "env": [] },
          "license": "none/unspecified",
          "maintainer": "dgreenheck",
          "signal": { "stars": 1000, "last_commit": "2026-04-10", "reputability": "individual" },
          "default_installed": false,
          "safety": "clean (no license — do not vendor/redistribute until clarified)",
          "tags": ["webgpu", "three.js", "graphics", "frontend"]
        },
        {
          "id": "swiftui-design-skill",
          "name": "SwiftUI Design Skill",
          "type": "skill",
          "domain": "frontend-design",
          "description": "Anti-AI-slop SwiftUI design rules for Apple/mobile builders.",
          "source": "https://github.com/Wholiver/swiftui-design-skill",
          "install": { "method": "submodule", "command": "git submodule add https://github.com/Wholiver/swiftui-design-skill .claude/skills/ext/swiftui-design", "env": [] },
          "license": "MIT",
          "maintainer": "Wholiver",
          "signal": { "stars": 138, "last_commit": "2026-05-01", "reputability": "individual" },
          "default_installed": false,
          "safety": "clean",
          "tags": ["swiftui", "design", "apple", "mobile", "ios"]
        },
        {
          "id": "animation-principles",
          "name": "Animation Principles",
          "type": "skill",
          "domain": "frontend-design",
          "description": "Genre-template skill for motion / animation design principles (pure prose).",
          "source": "https://github.com/dylantarre/animation-principles",
          "install": { "method": "submodule", "command": "git submodule add https://github.com/dylantarre/animation-principles .claude/skills/ext/animation-principles", "env": [] },
          "license": "MIT",
          "maintainer": "dylantarre",
          "signal": { "stars": 47, "last_commit": "2025-12-30", "reputability": "individual" },
          "default_installed": false,
          "safety": "clean — pure-prose, zero scripts/installers; stale (~Dec 2025), unmaintained",
          "tags": ["animation", "motion", "ui", "frontend"]
        },
        {
          "id": "emilkowalski-skill",
          "name": "Emil Kowalski Motion Skill",
          "type": "skill",
          "domain": "frontend-design",
          "description": "Motion / interaction design skill from a renowned motion author (Sonner, Vaul).",
          "source": "https://github.com/emilkowalski/skill",
          "install": { "method": "submodule", "command": "git submodule add https://github.com/emilkowalski/skill .claude/skills/ext/emilkowalski-skill", "env": [] },
          "license": "none/unspecified",
          "maintainer": "emilkowalski",
          "signal": { "stars": 2400, "last_commit": "2026-03-25", "reputability": "individual" },
          "default_installed": false,
          "safety": "clean (no license — do not vendor/redistribute until clarified); stale (~Mar 2026)",
          "tags": ["motion", "animation", "interaction", "frontend"]
        },
        {
          "id": "brand-design-md",
          "name": "Brand Design (md)",
          "type": "skill",
          "domain": "frontend-design",
          "description": "Brand-design reference in markdown.",
          "source": "https://github.com/zephyrwang6/brand-design-md",
          "install": { "method": "submodule", "command": "git submodule add https://github.com/zephyrwang6/brand-design-md .claude/skills/ext/brand-design-md", "env": [] },
          "license": "none/unspecified",
          "maintainer": "zephyrwang6",
          "signal": { "stars": 88, "last_commit": "2026-04-10", "reputability": "individual" },
          "default_installed": false,
          "safety": "clean (no license — do not vendor/redistribute until clarified); overlaps solana-new brand-design",
          "tags": ["branding", "design", "frontend"]
        },
        {
          "id": "ux-writing-skill",
          "name": "UX Writing Skill",
          "type": "skill",
          "domain": "ux-writing",
          "description": "Systematic UX microcopy: onboarding, error, empty-state and button copy with quality standards.",
          "source": "https://github.com/content-designer/ux-writing-skill",
          "install": { "method": "submodule", "command": "git submodule add https://github.com/content-designer/ux-writing-skill .claude/skills/ext/ux-writing", "env": [] },
          "license": "MIT",
          "maintainer": "content-designer",
          "signal": { "stars": 112, "last_commit": "2026-05-26", "reputability": "individual" },
          "default_installed": false,
          "safety": "clean (one build-skill.sh builder, not runtime)",
          "tags": ["ux-writing", "microcopy", "content-design", "onboarding"]
        },
        {
          "id": "design-skills",
          "name": "Design Skills (UX process)",
          "type": "skill",
          "domain": "ux-writing",
          "description": "UX-process breadth: 10 skills incl. ux-research, design-critique, journey-mapping, a11y-audit.",
          "source": "https://github.com/cuellarfr/design-skills",
          "install": { "method": "submodule", "command": "git submodule add https://github.com/cuellarfr/design-skills .claude/skills/ext/design-skills", "env": [] },
          "license": "MIT",
          "maintainer": "cuellarfr",
          "signal": { "stars": 31, "last_commit": "2026-05-04", "reputability": "individual" },
          "default_installed": false,
          "safety": "clean",
          "tags": ["ux-research", "design-critique", "journey-mapping", "accessibility", "ux"]
        },
        {
          "id": "scientific-agent-skills",
          "name": "Scientific Agent Skills",
          "type": "skill",
          "domain": "data",
          "description": "140 science skills + 100 database connectors; best-in-class for data-heavy builders.",
          "source": "https://github.com/K-Dense-AI/scientific-agent-skills",
          "install": { "method": "submodule", "command": "git submodule add https://github.com/K-Dense-AI/scientific-agent-skills .claude/skills/ext/scientific-agent-skills", "env": [] },
          "license": "MIT",
          "maintainer": "K-Dense-AI",
          "signal": { "stars": 28300, "last_commit": "2026-06-15", "reputability": "org" },
          "default_installed": false,
          "safety": "clean",
          "tags": ["science", "data", "database-connectors", "research"]
        },
        {
          "id": "claude-d3js-skill",
          "name": "Claude D3.js Skill",
          "type": "skill",
          "domain": "data",
          "description": "D3 data-visualization skill for dashboards.",
          "source": "https://github.com/chrisvoncsefalvay/claude-d3js-skill",
          "install": { "method": "submodule", "command": "git submodule add https://github.com/chrisvoncsefalvay/claude-d3js-skill .claude/skills/ext/d3js", "env": [] },
          "license": "none/unspecified",
          "maintainer": "chrisvoncsefalvay",
          "signal": { "stars": 192, "last_commit": "2025-10-18", "reputability": "individual" },
          "default_installed": false,
          "safety": "clean (no license — do not vendor/redistribute until clarified); stale (~Oct 2025)",
          "tags": ["d3", "data-viz", "dashboards", "data"]
        },
        {
          "id": "claude-skills-marketplace",
          "name": "Claude Skills Marketplace (mhattingpete)",
          "type": "plugin",
          "domain": "dev-workflow",
          "description": "Plugin marketplace: git + test + code-review pack.",
          "source": "https://github.com/mhattingpete/claude-skills-marketplace",
          "install": { "method": "plugin-marketplace", "command": "/plugin marketplace add mhattingpete/claude-skills-marketplace", "env": [] },
          "license": "Apache-2.0",
          "maintainer": "mhattingpete",
          "signal": { "stars": 607, "last_commit": "2026-03-06", "reputability": "individual" },
          "default_installed": false,
          "safety": "clean; borderline stale (~Mar 2026)",
          "tags": ["git", "testing", "code-review", "marketplace", "workflow"]
        },
        {
          "id": "playwright-skill",
          "name": "Playwright Skill",
          "type": "skill",
          "domain": "testing-qa",
          "description": "De-facto Playwright skill for browser automation and webapp testing.",
          "source": "https://github.com/lackeyjb/playwright-skill",
          "install": { "method": "submodule", "command": "git submodule add https://github.com/lackeyjb/playwright-skill .claude/skills/ext/playwright", "env": [] },
          "license": "MIT",
          "maintainer": "lackeyjb",
          "signal": { "stars": 2800, "last_commit": "2025-12-19", "reputability": "individual" },
          "default_installed": false,
          "safety": "clean; stale (~Dec 2025)",
          "tags": ["playwright", "browser", "testing", "qa", "e2e"]
        },
        {
          "id": "vercel-plugin",
          "name": "Vercel Plugin",
          "type": "plugin",
          "domain": "frontend-design",
          "description": "Full Vercel plugin: 28 skills + 3 agents + official read-only Vercel MCP (Next.js/React/AI-SDK frontend bundle).",
          "source": "https://github.com/vercel/vercel-plugin",
          "install": { "method": "plugin-marketplace", "command": "/plugin marketplace add vercel/vercel-plugin", "env": ["VERCEL_PLUGIN_TELEMETRY=off (opt-out of default telemetry)"] },
          "license": "Apache-2.0",
          "maintainer": "vercel",
          "signal": { "stars": 190, "last_commit": "2026-06-15", "reputability": "org" },
          "default_installed": false,
          "safety": "caution: telemetry ON by default (anonymized DAU pings, no content); opt-out VERCEL_PLUGIN_TELEMETRY=off",
          "tags": ["vercel", "nextjs", "react", "ai-sdk", "frontend", "deployment"]
        },
        {
          "id": "meteora-sdk-skill",
          "name": "Meteora SDK Skill",
          "type": "skill",
          "domain": "solana-defi",
          "description": "Meteora DLMM SDK-depth skill (net-new vs solana-new; sendai already ships a meteora skill — add only for SDK-level depth).",
          "source": "https://github.com/MeteoraAg/meteora-sdk-skill",
          "install": { "method": "submodule", "command": "git submodule add https://github.com/MeteoraAg/meteora-sdk-skill .claude/skills/ext/meteora-sdk", "env": [] },
          "license": "unspecified",
          "maintainer": "MeteoraAg",
          "signal": { "stars": null, "last_commit": "2026-06", "reputability": "org" },
          "default_installed": false,
          "safety": "clean; overlaps the bundled sendai meteora skill — confirm SDK-depth delta before adding",
          "tags": ["meteora", "dlmm", "defi", "sdk", "solana"]
        },
        {
          "id": "x402-proxy-mcp",
          "name": "x402 Proxy MCP",
          "type": "mcp",
          "domain": "solana-infra",
          "description": "Agent-payments proxy MCP (x402). Net-new vs solana-new (its x402-mcp is a different git-clone impl).",
          "source": "https://www.npmjs.com/package/x402-proxy",
          "install": { "method": "npx", "command": "claude mcp add x402-proxy -- npx -y x402-proxy", "env": [] },
          "license": "unspecified",
          "maintainer": "x402",
          "signal": { "stars": null, "last_commit": null, "reputability": "emerging — verify before install" },
          "default_installed": false,
          "safety": "caution: BIP-39 key custody for agent payments — isolate keys, explicit opt-in only, never a default",
          "tags": ["x402", "payments", "mcp", "key-custody", "solana"]
        },
        {
          "id": "pyth-pro-mcp",
          "name": "Pyth Pro MCP",
          "type": "mcp",
          "domain": "solana-infra",
          "description": "Pyth Pro price-feed MCP: 500+ feeds, low latency. Net-new vs solana-new (Pyth appears only as a dependency keyword there).",
          "source": "https://www.npmjs.com/package/@pythnetwork/pyth-mcp",
          "install": { "method": "npx", "command": "claude mcp add pyth-pro -- npx -y @pythnetwork/pyth-mcp", "env": ["PYTH_API_KEY"] },
          "license": "unspecified",
          "maintainer": "pyth-network",
          "signal": { "stars": null, "last_commit": null, "reputability": "org" },
          "default_installed": false,
          "safety": "caution: paid API key (billable); no custody risk",
          "tags": ["pyth", "oracle", "price-feeds", "mcp", "solana"]
        },
        {
          "id": "chainstack-mcp",
          "name": "Chainstack MCP",
          "type": "mcp",
          "domain": "solana-infra",
          "description": "Hosted unified multi-chain RPC MCP. Net-new vs solana-new.",
          "source": "https://mcp.chainstack.com/mcp",
          "install": { "method": "npx", "command": "claude mcp add --transport http chainstack https://mcp.chainstack.com/mcp", "env": [] },
          "license": "unspecified",
          "maintainer": "chainstack",
          "signal": { "stars": null, "last_commit": null, "reputability": "org" },
          "default_installed": false,
          "safety": "caution: hosted multi-chain RPC — check data-retention policy",
          "tags": ["rpc", "multi-chain", "mcp", "hosted", "solana"]
        },
        {
          "id": "noesis-mcp",
          "name": "Noesis MCP",
          "type": "mcp",
          "domain": "solana-infra",
          "description": "Hosted token-intelligence MCP. Net-new vs solana-new.",
          "source": "https://noesisapi.dev/mcp",
          "install": { "method": "npx", "command": "claude mcp add --transport http noesis https://noesisapi.dev/mcp", "env": [] },
          "license": "unspecified",
          "maintainer": "noesis",
          "signal": { "stars": null, "last_commit": null, "reputability": "emerging — verify before install" },
          "default_installed": false,
          "safety": "caution: hosted token-intel — verify provenance/traction before trusting",
          "tags": ["token-intel", "mcp", "hosted", "solana"]
        },
        {
          "id": "dexpaprika-mcp",
          "name": "DexPaprika MCP",
          "type": "mcp",
          "domain": "solana-infra",
          "description": "Free, no-key DEX market-data MCP. Net-new vs solana-new (its DEX-data MCP is a different provider).",
          "source": "https://www.npmjs.com/package/dexpaprika-mcp",
          "install": { "method": "npx", "command": "claude mcp add dexpaprika -- npx -y dexpaprika-mcp", "env": [] },
          "license": "unspecified",
          "maintainer": "dexpaprika",
          "signal": { "stars": null, "last_commit": null, "reputability": "org" },
          "default_installed": false,
          "safety": "clean; free no-key DEX market data, low-risk read-only",
          "tags": ["dex", "market-data", "mcp", "solana"]
        },
        {
          "id": "phantom-mcp",
          "name": "Phantom MCP",
          "type": "mcp",
          "domain": "solana-infra",
          "description": "Phantom wallet MCP — can sign/submit transactions. Also cataloged in solana-new (phantom-mcp-server); kept here because the signing-custody warning is load-bearing.",
          "source": "https://www.npmjs.com/package/@phantom/mcp-server",
          "install": { "method": "npx", "command": "claude mcp add phantom -- npx -y @phantom/mcp-server", "env": [] },
          "license": "unspecified",
          "maintainer": "phantom",
          "signal": { "stars": null, "last_commit": null, "reputability": "org" },
          "default_installed": false,
          "safety": "caution: wallet signing — can sign/submit transactions; explicit user consent only, never a default (key-custody risk)",
          "tags": ["phantom", "wallet", "signing", "mcp", "solana"]
        },
        {
          "id": "gmem",
          "name": "gmem",
          "type": "skill",
          "domain": "solana-infra",
          "description": "Agent memory layer (watchlist — young/unverified).",
          "source": "https://github.com/yksanjo/gmem",
          "install": null,
          "license": "unverified",
          "maintainer": "yksanjo",
          "signal": { "stars": null, "last_commit": null, "reputability": "emerging — verify before install" },
          "default_installed": false,
          "safety": "caution: unverified — confirm maintenance + license before any use",
          "tags": ["memory", "agent", "watchlist", "solana"]
        },
        {
          "id": "snap-protocol",
          "name": "Snap Protocol",
          "type": "skill",
          "domain": "solana-infra",
          "description": "Snapshot/state protocol skill (watchlist — young/unverified).",
          "source": "https://github.com/agentzeny/snap-public",
          "install": null,
          "license": "unverified",
          "maintainer": "agentzeny",
          "signal": { "stars": null, "last_commit": null, "reputability": "emerging — verify before install" },
          "default_installed": false,
          "safety": "caution: early — verify reachability + traction before any use",
          "tags": ["snapshot", "state", "protocol", "watchlist", "solana"]
        },
        {
          "id": "seeker-skills",
          "name": "Seeker Skills",
          "type": "skill",
          "domain": "solana-infra",
          "description": "Solana Seeker (mobile) skills (watchlist — young/unverified). Cross-check vs ext/solana-mobile coverage.",
          "source": "https://github.com/Sarthib7/seeker-skills",
          "install": { "method": "submodule", "command": "git submodule add https://github.com/Sarthib7/seeker-skills .claude/skills/ext/seeker-skills", "env": [] },
          "license": "unverified",
          "maintainer": "Sarthib7",
          "signal": { "stars": null, "last_commit": null, "reputability": "emerging — verify before install" },
          "default_installed": false,
          "safety": "caution: niche mobile, unverified — cross-check vs ext/solana-mobile before adding",
          "tags": ["seeker", "mobile", "watchlist", "solana"]
        },
        {
          "id": "sati",
          "name": "SATI (SAID/SATI/AIP)",
          "type": "skill",
          "domain": "identity",
          "description": "Agent-identity standards (SAID/SATI/AIP). Not a skill yet — emerging standard (watchlist). Net-new vs solana-new.",
          "source": "https://github.com/cascade-protocol/sati",
          "install": null,
          "license": "unverified",
          "maintainer": "cascade-protocol",
          "signal": { "stars": null, "last_commit": null, "reputability": "emerging — verify before install" },
          "default_installed": false,
          "safety": "caution: emerging standard, not a skill yet — monitor for adoption",
          "tags": ["agent-identity", "standard", "watchlist", "solana"]
        },
        {
          "id": "composio-awesome-claude-skills",
          "name": "Composio Awesome Claude Skills",
          "type": "aggregator",
          "domain": "dev-workflow",
          "description": "Scout source: best current skills-specific aggregator (1000+, domain-grouped). Not installable.",
          "source": "https://github.com/ComposioHQ/awesome-claude-skills",
          "install": null,
          "license": "unspecified",
          "maintainer": "ComposioHQ",
          "signal": { "stars": 64700, "last_commit": "2026-05-22", "reputability": "org" },
          "default_installed": false,
          "safety": "clean — discovery source only, nothing executed",
          "tags": ["aggregator", "scout", "skills", "discovery"]
        },
        {
          "id": "travisvn-awesome-claude-skills",
          "name": "travisvn Awesome Claude Skills",
          "type": "aggregator",
          "domain": "dev-workflow",
          "description": "Scout source: tight, high-signal, well-maintained skills list. Not installable.",
          "source": "https://github.com/travisvn/awesome-claude-skills",
          "install": null,
          "license": "unspecified",
          "maintainer": "travisvn",
          "signal": { "stars": 13500, "last_commit": "2026-04-28", "reputability": "individual" },
          "default_installed": false,
          "safety": "clean — discovery source only, nothing executed",
          "tags": ["aggregator", "scout", "skills", "discovery"]
        },
        {
          "id": "buildwithclaude",
          "name": "Build With Claude",
          "type": "aggregator",
          "domain": "dev-workflow",
          "description": "Scout source: live searchable hub (buildwithclaude.com); best for plugins/marketplaces. Not installable.",
          "source": "https://github.com/davepoon/buildwithclaude",
          "install": null,
          "license": "unspecified",
          "maintainer": "davepoon",
          "signal": { "stars": 3100, "last_commit": "2026-06-15", "reputability": "individual" },
          "default_installed": false,
          "safety": "clean — discovery source only, nothing executed",
          "tags": ["aggregator", "scout", "plugins", "marketplaces", "discovery"]
        },
        {
          "id": "hesreallyhim-awesome-claude-code",
          "name": "Awesome Claude Code",
          "type": "aggregator",
          "domain": "dev-workflow",
          "description": "Scout source: canonical Claude Code list (README mid-reorg). Not installable.",
          "source": "https://github.com/hesreallyhim/awesome-claude-code",
          "install": null,
          "license": "unspecified",
          "maintainer": "hesreallyhim",
          "signal": { "stars": 46500, "last_commit": "2026-04-27", "reputability": "individual" },
          "default_installed": false,
          "safety": "clean — discovery source only, nothing executed",
          "tags": ["aggregator", "scout", "claude-code", "discovery"]
        },
        {
          "id": "voltagent-awesome-claude-code-subagents",
          "name": "VoltAgent Awesome Claude Code Subagents",
          "type": "aggregator",
          "domain": "dev-workflow",
          "description": "Scout source: 100+ subagents by domain (agents, not skills). Not installable.",
          "source": "https://github.com/VoltAgent/awesome-claude-code-subagents",
          "install": null,
          "license": "unspecified",
          "maintainer": "VoltAgent",
          "signal": { "stars": 21800, "last_commit": "2026-06-15", "reputability": "org" },
          "default_installed": false,
          "safety": "clean — discovery source only, nothing executed",
          "tags": ["aggregator", "scout", "subagents", "discovery"]
        },
        {
          "id": "anthropics-claude-plugins-community",
          "name": "Anthropic Claude Plugins Community Index",
          "type": "aggregator",
          "domain": "dev-workflow",
          "description": "Scout source: 2,201-plugin community index; discovery source, NOT first-party-vetted. Not installable.",
          "source": "https://github.com/anthropics/claude-plugins-community",
          "install": null,
          "license": "Apache-2.0",
          "maintainer": "anthropics",
          "signal": { "stars": 183, "last_commit": "2026-06-15", "reputability": "official" },
          "default_installed": false,
          "safety": "clean — community index, not first-party-vetted; verify each entry before installing",
          "tags": ["aggregator", "scout", "plugins", "community", "discovery"]
        },
        {
          "id": "nansen-mcp",
          "name": "Nansen",
          "type": "mcp",
          "domain": "data",
          "description": "Institutional on-chain analytics via Nansen's hosted MCP: wallet labeling/profiler, smart-money flows, token analytics (DEX trades, OHLCV, screener, quant scores), PnL, holder analysis. 18+ chains including Solana. Net-new vs solana-new.",
          "source": "https://github.com/nansen-ai/nansen-cli",
          "install": {
            "method": "remote-http-mcp",
            "command": "claude mcp add --transport http nansen https://mcp.nansen.ai/ra/mcp --header \"NANSEN-API-KEY: ${NANSEN_API_KEY}\"",
            "env": ["NANSEN_API_KEY"]
          },
          "license": "proprietary hosted MCP; nansen-cli MIT",
          "maintainer": "Nansen (first-party)",
          "signal": { "stars": null, "last_commit": "2026-06-11", "reputability": "high" },
          "default_installed": false,
          "safety": "caution: SaaS data-routing — queries and API key sent to mcp.nansen.ai (Nansen servers); key passed in request header; free tier 100 credits, paid ~$0.001/credit or $0.01–$0.05/x402 call; opt-in only",
          "tags": ["analytics", "wallet-labeling", "smart-money", "on-chain-data", "solana", "multi-chain", "paid"]
        }
      ]
    }
    
  • SKILL.md 11.1 KB
    ---
    name: solana-dev
    description: Routing hub for Solana development. Maps a task to the one reference to read first in the ext/ skill submodules or the kit's local skills.
    user-invocable: true
    ---
    
    # Solana skill hub
    
    Find the task, read the linked file, and follow further links only as needed. Paths are relative to this file.
    
    When sources overlap: the program-code house rules in the project instruction file (`CLAUDE.md`, or `AGENTS.md` in `--agents` installs) win; a protocol's official skill wins for its own SDK (Jupiter, Metaplex, Helius); [ext/solana-dev](ext/solana-dev/skills/solana-dev/SKILL.md) wins for general Solana work; sendai and community skills fill gaps only.
    
    ## Programs
    
    | Task | Read |
    |------|------|
    | Any program, client or test work (entry point) | [solana-dev SKILL.md](ext/solana-dev/skills/solana-dev/SKILL.md) |
    | Anchor | [programs/anchor.md](ext/solana-dev/skills/solana-dev/references/programs/anchor.md); upgrading to 1.x: [migrating-v0.32-to-v1.md](ext/solana-dev/skills/solana-dev/references/anchor/migrating-v0.32-to-v1.md) |
    | Pinocchio, CU optimization | [programs/pinocchio.md](ext/solana-dev/skills/solana-dev/references/programs/pinocchio.md) |
    | Account and PDA design | [programs/design-patterns.md](ext/solana-dev/skills/solana-dev/references/programs/design-patterns.md) |
    | Tests: LiteSVM, Mollusk, Surfpool | [testing.md](ext/solana-dev/skills/solana-dev/references/testing.md), [surfpool/overview.md](ext/solana-dev/skills/solana-dev/references/surfpool/overview.md) |
    | Error codes, failing transactions | [common-errors.md](ext/solana-dev/skills/solana-dev/references/common-errors.md) |
    | Toolchain version pairing | [compatibility-matrix.md](ext/solana-dev/skills/solana-dev/references/compatibility-matrix.md) |
    | Security review | [security.md](ext/solana-dev/skills/solana-dev/references/security.md), [safe-solana-builder](ext/safe-solana-builder/SKILL.md) (security-first scaffolding, Anchor/native/Pinocchio) |
    | Financial math, Quasar zero-copy | [RUST.md](ext/quicknode-anchor/skills/solana/RUST.md), [ANCHOR.md](ext/quicknode-anchor/skills/solana/ANCHOR.md), [QUASAR.md](ext/quicknode-anchor/skills/solana/QUASAR.md) from [quicknode-anchor](ext/quicknode-anchor/); reference files only, skip that repo's SKILL.md workflow layer |
    | Formal verification (Lean 4) | [qedgen](ext/qedgen/skills/qedgen/SKILL.md) from [QEDGen](ext/qedgen/); needs the `qedgen` CLI and `MISTRAL_API_KEY` |
    | Port from Solidity/EVM | [eth-to-sol](ext/eth-to-sol/SKILL.md) from [eth-to-sol](ext/eth-to-sol/): [type-mapping](ext/eth-to-sol/translation/type-mapping.md), [pattern-mapping](ext/eth-to-sol/translation/pattern-mapping.md), [stdlib-mapping](ext/eth-to-sol/translation/stdlib-mapping.md), [mental-model](ext/eth-to-sol/translation/mental-model.md), [translation/](ext/eth-to-sol/translation/), [security/](ext/eth-to-sol/security/), [optimization/](ext/eth-to-sol/optimization/); concept map: [solana-vs-evm.md](ext/solana-new/skills/idea/solana-beginner/references/solana-vs-evm.md) |
    
    Anchor 1.x defaults this kit uses (not all spelled out upstream): SPL transfers through `token_interface::transfer_checked`, account space `T::DISCRIMINATOR.len() + T::INIT_SPACE`, Rust LiteSVM tests under `programs/<name>/tests/` (`anchor test` runs Surfpool).
    
    ## Clients and frontend
    
    | Task | Read |
    |------|------|
    | Wallet connection, React hooks, `@solana/kit` UI | [frontend.md](ext/solana-dev/skills/solana-dev/references/frontend.md) |
    | Transactions, Kit and web3.js boundary | [kit-web3-interop.md](ext/solana-dev/skills/solana-dev/references/kit-web3-interop.md) |
    | web3.js to Kit migration | [solana-kit-migration/](ext/sendai/skills/solana-kit-migration/), [solana-kit/](ext/sendai/skills/solana-kit/) |
    | Clients generated from an IDL (Codama, Shank) | [idl-codegen.md](ext/solana-dev/skills/solana-dev/references/idl-codegen.md) |
    | Payments, Solana Pay, Kora | [payments.md](ext/solana-dev/skills/solana-dev/references/payments.md) |
    | Official doc links | [resources.md](ext/solana-dev/skills/solana-dev/references/resources.md) |
    | Vercel, Next.js, AI SDK, v0 | [ext/vercel/skills/](ext/vercel/skills/) from [Vercel](ext/vercel/) |
    
    ## Tokens and NFTs
    
    | Task | Read |
    |------|------|
    | Token-2022 extensions (hooks, fees, metadata, soulbound) | [token-2022.md](token-2022.md) |
    | Confidential transfers | [confidential-transfers.md](ext/solana-dev/skills/solana-dev/references/confidential-transfers.md) |
    | NFTs: Core, Token Metadata, Bubblegum, Candy Machine, Umi | [metaplex](ext/metaplex/skills/metaplex/SKILL.md) (official) |
    
    ## DeFi, RPC and data
    
    | Task | Read |
    |------|------|
    | Jupiter swap, lend, perps, trigger, recurring | [integrating-jupiter](ext/jupiter/skills/integrating-jupiter/SKILL.md) (official); also [jupiter-lend](ext/jupiter/skills/jupiter-lend/SKILL.md), [jupiter-swap-migration](ext/jupiter/skills/jupiter-swap-migration/SKILL.md), [jupiter-vrfd](ext/jupiter/skills/jupiter-vrfd/SKILL.md) |
    | Helius RPC, DAS, webhooks, Sender, priority fees | [helius](ext/helius/helius-skills/helius/SKILL.md) (official) |
    | SVM internals, consensus, validators, SIMDs | [svm](ext/helius/helius-skills/svm/SKILL.md) |
    
    Other protocols from [SendAI](ext/sendai/skills/): perps [phoenix](ext/sendai/skills/phoenix/) and leverage [lavarage](ext/sendai/skills/lavarage/); AMMs [raydium](ext/sendai/skills/raydium/), [meteora](ext/sendai/skills/meteora/), [orca](ext/sendai/skills/orca/); lending [kamino](ext/sendai/skills/kamino/), [marginfi](ext/sendai/skills/marginfi/); LSTs [sanctum](ext/sendai/skills/sanctum/); launches [pumpfun](ext/sendai/skills/pumpfun/); oracles [pyth](ext/sendai/skills/pyth/), [switchboard](ext/sendai/skills/switchboard/); multisig [squads](ext/sendai/skills/squads/); bridging [debridge](ext/sendai/skills/debridge/), [lifi](ext/sendai/skills/lifi/); encrypted compute [arcium](ext/sendai/skills/arcium/); ZK compression [light-protocol](ext/sendai/skills/light-protocol/); data [birdeye](ext/sendai/skills/birdeye/), [wallet-analysis](ext/sendai/skills/wallet-analysis/); RPC [carbium](ext/sendai/skills/carbium/), [quicknode](ext/sendai/skills/quicknode/); order book [manifest](ext/sendai/skills/manifest/); order flow [dflow](ext/sendai/skills/dflow/); on-chain games [magicblock](ext/sendai/skills/magicblock/); account cleanup [sol-incinerator](ext/sendai/skills/sol-incinerator/); agents [solana-agent-kit](ext/sendai/skills/solana-agent-kit/); wallets [phantom-connect](ext/sendai/skills/phantom-connect/); scanning [vulnhunter](ext/sendai/skills/vulnhunter/). SendAI's own jupiter, metaplex and helius folders are older copies; the official skills above supersede them.
    
    ## Security tooling
    
    - [Trail of Bits](ext/trailofbits/plugins/building-secure-contracts/skills/): [solana-vulnerability-scanner](ext/trailofbits/plugins/building-secure-contracts/skills/solana-vulnerability-scanner/), [audit-prep-assistant](ext/trailofbits/plugins/building-secure-contracts/skills/audit-prep-assistant/), [code-maturity-assessor](ext/trailofbits/plugins/building-secure-contracts/skills/code-maturity-assessor/), [token-integration-analyzer](ext/trailofbits/plugins/building-secure-contracts/skills/token-integration-analyzer/), [guidelines-advisor](ext/trailofbits/plugins/building-secure-contracts/skills/guidelines-advisor/)
    - [Ghost Security](ext/ghostsecurity/plugins/ghost/skills/) AppSec: [scan-code](ext/ghostsecurity/plugins/ghost/skills/scan-code/) with per-stack [criteria](ext/ghostsecurity/plugins/ghost/skills/scan-code/criteria/), [scan-deps](ext/ghostsecurity/plugins/ghost/skills/scan-deps/), [scan-secrets](ext/ghostsecurity/plugins/ghost/skills/scan-secrets/), [repo-context](ext/ghostsecurity/plugins/ghost/skills/repo-context/), [validate](ext/ghostsecurity/plugins/ghost/skills/validate/), [report](ext/ghostsecurity/plugins/ghost/skills/report/). Its proxy, scan-deps and scan-secrets files include unpinned `curl ... | bash` installers; run them only with the user's consent.
    - [Anthropic defending-code](ext/defending-code/): [threat-model](ext/defending-code/.claude/skills/threat-model/), [vuln-scan](ext/defending-code/.claude/skills/vuln-scan/), [triage](ext/defending-code/.claude/skills/triage/), [patch](ext/defending-code/.claude/skills/patch/), methodology [docs](ext/defending-code/docs/)
    
    ## Deploy, infra, backend
    
    - [deployment.md](deployment.md): devnet and mainnet flow, verifiable builds, Squads multisig upgrades, rollback
    - [backend-async.md](backend-async.md): Rust services and indexers that talk to Solana
    - [Cloudflare](ext/cloudflare/skills/): [workers-best-practices](ext/cloudflare/skills/workers-best-practices/), [agents-sdk](ext/cloudflare/skills/agents-sdk/), [sandbox-stable](ext/cloudflare/skills/sandbox-stable/), [durable-objects](ext/cloudflare/skills/durable-objects/), [wrangler](ext/cloudflare/skills/wrangler/)
    
    ## Games and mobile
    
    - [solana-game](ext/solana-game/skill/): [SKILL.md](ext/solana-game/skill/SKILL.md), [unity-sdk.md](ext/solana-game/skill/unity-sdk.md), [playsolana.md](ext/solana-game/skill/playsolana.md) (PSG1, PlayDex, PlayID), [game-architecture.md](ext/solana-game/skill/game-architecture.md), [mobile.md](ext/solana-game/skill/mobile.md), [csharp-patterns.md](ext/solana-game/skill/csharp-patterns.md)
    - [solana-mobile](ext/solana-mobile/skills/): [solana-mobile-wallet](ext/solana-mobile/skills/solana-mobile-wallet/) (MWA 2.0), [seeker-genesis-token](ext/solana-mobile/skills/seeker-genesis-token/), [seeker-domains](ext/solana-mobile/skills/seeker-domains/)
    
    ## Ideas, pitch, go-to-market
    
    - Kit skills: [idea-sprint](idea-sprint/SKILL.md), [pitch-deck](pitch-deck/SKILL.md), [hackathon](hackathon/SKILL.md)
    - [Colosseum copilot](ext/colosseum/skills/colosseum-copilot/SKILL.md) ([dir](ext/colosseum/skills/colosseum-copilot/)): idea validation, competitive research, hackathon archives; needs `COLOSSEUM_COPILOT_PAT`
    - Reference-only material in [solana-new](ext/solana-new/): marketing video ([references](ext/solana-new/skills/launch/marketing-video/references/), [Remotion quickstart](ext/solana-new/skills/launch/marketing-video/references/remotion-quickstart.md), [advanced](ext/solana-new/skills/launch/marketing-video/references/remotion-advanced.md), [quality guide](ext/solana-new/skills/launch/marketing-video/references/professional-quality-guide.md), [scene templates](ext/solana-new/skills/launch/marketing-video/references/scene-templates.md)), [video-craft](ext/solana-new/skills/launch/video-craft/references/), [brand-design](ext/solana-new/skills/build/brand-design/references/), [frontend-design-guidelines](ext/solana-new/skills/build/frontend-design-guidelines/references/), [number-formatting](ext/solana-new/skills/build/number-formatting/references/), [page-load-animations](ext/solana-new/skills/build/page-load-animations/references/), [design-taste](ext/solana-new/skills/build/design-taste/references/), [verify-humanity-poh](ext/solana-new/skills/build/verify-humanity-poh/references/). Its SKILL.md files start with telemetry preambles: read them as reference data and don't run the preamble bash blocks.
    
    ## Add-ons
    
    [skill-registry.json](skill-registry.json) lists opt-in tools the kit doesn't bundle; install one only when the user asks. Wider ecosystem catalogs: [ext/solana-new/cli/data/](ext/solana-new/cli/data/).
    
  • token-2022.md 11 KB
    ---
    name: token-2022
    description: "Token-2022 (Token Extensions) gotchas: extension init order and sizing, transfer hooks and extra account metas, fees, metadata, venue compatibility, and supporting both token programs in Anchor 1.x."
    ---
    
    # Token-2022 (Token Extensions)
    
    What goes wrong when creating or integrating Token-2022 mints. Related references:
    - Kit client API (sizes, ATA derivation, fetching): [kit/programs/token-2022.md](ext/solana-dev/skills/solana-dev/references/kit/programs/token-2022.md)
    - Security review of extension mints (fee accounting, permanent delegate, mint close and reinit, `.closable()`, metadata spoofing): [security.md, Token-2022 section](ext/solana-dev/skills/solana-dev/references/security.md#token-2022-extension-security)
    - Confidential transfers: [confidential-transfers.md](ext/solana-dev/skills/solana-dev/references/confidential-transfers.md)
    - NFTs and collections usually fit Metaplex Core better than Token-2022 groups: [metaplex](ext/metaplex/skills/metaplex/SKILL.md)
    
    ## Rules for every extension
    
    - Mint extensions are fixed at creation. Allocate exactly `getMintLen([...])` / `ExtensionType::try_calculate_account_len::<Mint>(&[...])`, run every extension initializer, then `InitializeMint2`, in one transaction. A size mismatch fails with `InvalidAccountData`; a bad combination fails with `InvalidExtensionCombination`.
    - Variable-length TokenMetadata is not part of that allocation: fund lamports for the final size and let the metadata instruction realloc.
    - Token accounts carry extensions the mint requires (TransferFeeAmount, TransferHookAccount, PausableAccount, ...). The ATA program and Anchor `init` with `token::`/`associated_token::` size them; manual creation must use `getAccountLenForMint` or the `GetAccountDataSize` instruction. Owner toggles (MemoTransfer, CpiGuard) on an account created without room for them need `Reallocate` first.
    - ATAs are derived with the token program as a seed. Pass the Token-2022 ID (`TokenzQdBNbLqP5VEhdkAS6EPFLC1PHnBqCXEpPxuEb`) to ATA derivation, `getMint`/`getAccount`, and ATA creation, or you get a different address.
    - Transfer with `transfer_checked`; plain `transfer` fails with `MintRequiredForTransfer` on fee and hook mints. `transfer_checked_with_fee` asserts the expected fee.
    - Integrations read the mint's extensions up front and allow-list what they support: `getExtensionTypes(mint.tlvData)` (web3.js), `mint.data.extensions` (Kit), `anchor_spl::token_interface::get_mint_extension_data::<T>(&mint_info)` on-chain.
    
    ## Supporting both token programs (Anchor 1.x)
    
    ```rust
    use anchor_spl::token_interface::{self, Mint, TokenAccount, TokenInterface, TransferChecked};
    
    #[derive(Accounts)]
    pub struct Pay<'info> {
        #[account(mut, token::mint = mint, token::token_program = token_program)]
        pub from: InterfaceAccount<'info, TokenAccount>,
        #[account(mut, token::mint = mint, token::token_program = token_program)]
        pub to: InterfaceAccount<'info, TokenAccount>,
        #[account(mint::token_program = token_program)]
        pub mint: InterfaceAccount<'info, Mint>,
        pub authority: Signer<'info>,
        pub token_program: Interface<'info, TokenInterface>, // Token or Token-2022
    }
    
    pub fn pay(ctx: Context<Pay>, amount: u64) -> Result<()> {
        let accounts = TransferChecked {
            from: ctx.accounts.from.to_account_info(),
            mint: ctx.accounts.mint.to_account_info(),
            to: ctx.accounts.to.to_account_info(),
            authority: ctx.accounts.authority.to_account_info(),
        };
        // 1.x: CpiContext takes the program Pubkey, not an AccountInfo
        let cpi = CpiContext::new(ctx.accounts.token_program.key(), accounts);
        token_interface::transfer_checked(cpi, amount, ctx.accounts.mint.decimals)
    }
    ```
    
    - `token::token_program`, `mint::token_program` and `associated_token::token_program` bind each account to the program that was passed in.
    - Credit what arrived, not `amount`: with a transfer fee the destination receives less. `.reload()` after the CPI and use the balance delta.
    - Extension constraints on `init`: `extensions::metadata_pointer::{authority, metadata_address}`, `extensions::transfer_hook::{authority, program_id}`, `extensions::group_pointer::{authority, group_address}`, `extensions::group_member_pointer::{authority, member_address}`, `extensions::close_authority::authority`, `extensions::permanent_delegate::delegate`. Extensions without a constraint (e.g. TransferFeeConfig, NonTransferable): create the account with `try_calculate_account_len::<PodMint>`, call the matching `anchor_spl::token_interface::*_initialize` CPIs, then `initialize_mint2`.
    - The `spl-token-2022` and `spl-tlv-account-resolution` versions that pair with anchor-lang 1.x still return `solana-program-error` 2.x errors (Anchor uses 3.x), so convert with `.map_err(...)` at the boundary. For direct `spl-*` dependencies see [migrating-v0.32-to-v1.md](ext/solana-dev/skills/solana-dev/references/anchor/migrating-v0.32-to-v1.md), section 17.
    
    ## Transfer hooks
    
    ```rust
    use spl_discriminator::SplDiscriminate;
    use spl_tlv_account_resolution::{account::ExtraAccountMeta, seeds::Seed, state::ExtraAccountMetaList};
    use spl_transfer_hook_interface::instruction::ExecuteInstruction;
    
    // Anchor 1.x removed #[interface]; InitializeExtraAccountMetaListInstruction works the same way
    #[instruction(discriminator = ExecuteInstruction::SPL_DISCRIMINATOR_SLICE)]
    pub fn transfer_hook(ctx: Context<TransferHook>, amount: u64) -> Result<()> { /* ... */ }
    
    // Per-owner PDA: seeds reference Execute accounts by index (3 = source authority)
    let metas = vec![ExtraAccountMeta::new_with_seeds(
        &[Seed::Literal { bytes: b"allow".to_vec() }, Seed::AccountKey { index: 3 }],
        false, // is_signer
        true,  // is_writable
    ).map_err(|_| ProgramError::InvalidArgument)?];
    ExtraAccountMetaList::init::<ExecuteInstruction>(&mut meta_list.try_borrow_mut_data()?, &metas)
        .map_err(|_| ProgramError::InvalidAccountData)?;
    ```
    
    - Execute account order: 0 source, 1 mint, 2 destination, 3 source authority, 4 the ExtraAccountMetaList PDA (seeds `["extra-account-metas", mint]` under the hook program), then the extras in list order. Seeds can also use `Seed::AccountData` and `Seed::InstructionData` (the amount).
    - The base accounts arrive read-only with signer privileges dropped. Anything the hook writes must be an extra account marked writable in the list.
    - Create and initialize the meta-list PDA before the first transfer. Changing it later (`UpdateExtraAccountMetaList`) breaks clients and programs that cached the old list.
    - The hook runs after balances move (it sees post-transfer state) and is skipped on self-transfers. Check the `transferring` flag on the source/destination `TransferHookAccount`, plus the mint and ownership checks in security.md.
    - Clients resolve extras with Kit `getTransferCheckedWithTransferHookInstructionAsync` (`@solana-program/token-2022`) or web3.js `createTransferCheckedWithTransferHookInstruction`. Simulate before sending: the hook can reject for its own reasons.
    - A program that CPIs a transfer of a hook mint needs the hook program, the meta-list PDA and the extras (take them as `remaining_accounts`). `token_interface::transfer_checked` passes only the four base accounts, so use the token-2022 crate's `onchain::invoke_transfer_checked` or add them with `spl_transfer_hook_interface::onchain::add_extra_accounts_for_execute_cpi`.
    - Every transfer pays the hook's compute; keep it small.
    
    ## Extension notes
    
    - **Transfer fee**: withheld in the destination account. The active fee is `get_epoch_fee(current_epoch)`, because `SetTransferFee` takes effect two epochs later; do not read `newer_transfer_fee` blindly. Collect with `harvest_withheld_tokens_to_mint` (permissionless), then `withdraw_withheld_tokens_from_mint` (withdraw authority). Accounts holding withheld fees cannot close.
    - **Metadata pointer + TokenMetadata**: initialize the pointer before `InitializeMint2`. TokenMetadata can only live in the mint itself and needs the mint authority's signature. Initialize and `update_field` realloc and assume the rent is already there: web3.js `tokenMetadataInitializeWithRentTransfer` / `tokenMetadataUpdateFieldWithRentTransfer`; in Anchor, top up to `Rent::minimum_balance(new_len)` before `token_metadata_initialize` / `token_metadata_update_field`. Readers check that pointer and `metadata.mint` reference each other.
    - **Default account state (Frozen)**: every new account, including ATAs other people create, starts frozen and only the freeze authority can thaw it. Build the thaw (KYC) path before launch.
    - **Permanent delegate**: can transfer or burn from any holder. Many venues and users treat such mints as custodial.
    - **Non-transferable**: holders can still burn and close. Pointless with fees, hooks or confidential transfers.
    - **Interest-bearing, scaled UI amount**: display-only; raw balances and supply never change (scaled UI can schedule a new multiplier at a timestamp). Show amounts through the extension-aware conversion (`amountToUiAmount`), not `amount / 10^decimals`.
    - **CPI Guard** (set by the owner): inside a CPI, transfers and burns need a delegate instead of the owner's signature, approve is blocked, and close must pay the owner. Protocols that pull tokens by CPI with the user's signature fail for these users; use a top-level approve plus a delegate transfer.
    - **Required memo** (set by the owner): an incoming transfer needs a memo immediately before it at the same level: a top-level memo for a top-level transfer, a memo CPI right before a CPI transfer.
    - **Immutable owner**: Token-2022 ATAs always have it; manually created accounts initialize it before `InitializeAccount`.
    - **Mint close authority**: closing needs zero supply; see the close-and-reinitialize risk in security.md.
    - **Pausable**: the pause authority halts transfers, mints and burns. Vaults holding the token must tolerate failed withdrawals while paused.
    - **Group / member**: `max_size` is enforced and adding a member needs the group update authority. Wallet and venue support is thin.
    - **Confidential transfers**: check which cluster has the ZK ElGamal proof program enabled before building (the reference tracks it). A transfer spans several transactions with proof context accounts, incoming amounts land in a pending balance until `ApplyPendingBalance`, a fee mint also needs ConfidentialTransferFeeConfig, and a transfer hook cannot see amounts.
    
    ## Before launch
    
    - Check every target venue's extension policy. Example: Orca Whirlpools requires an issuer TokenBadge for PermanentDelegate, TransferHook, MintCloseAuthority, DefaultAccountState and Pausable, and does not support NonTransferable or group/member mints.
    - Authorities (fee config, withdraw, metadata and hook pointers, pause) outlive the launch. Put the ones you may still need on a multisig and revoke the rest.
    - Tests: LiteSVM or Mollusk for hook and fee logic ([testing.md](ext/solana-dev/skills/solana-dev/references/testing.md)). On a Surfpool fork, `surfnet_setTokenAccount` takes the Token-2022 program ID as its last param, and `surfnet_timeTravel` with `absoluteEpoch` crosses the two-epoch fee delay ([cheatcodes.md](ext/solana-dev/skills/solana-dev/references/surfpool/cheatcodes.md)).
    

Comments (0)

Sign in to join the conversation.

No comments yet.

Reviews (0)

No reviews yet.

Related